https mediation
34%
Total Score
50
67
50
50
The artifact contains only package.json, leaving no implementation files, documentation, or other published material to verify how the package works. This is a substantial transparency concern.
The package has only one release, published 11 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the package not being deprecated.
No build attestation, trusted publisher, or staged-publishing evidence is present. This limits publication transparency, although it is less significant than the package's age and minimal artifact.
One registry maintainer is listed, but this administrative record does not demonstrate active maintenance or contributor capacity. The release history provides the stronger evidence here.
The published artifact has no README, tests, changelog, or release notes. Missing tests and changelogs are normal in published artifacts, but the absent README weakens consumer guidance for this library.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.